GEO Performance Report Builder

Security checks across malware telemetry and agentic risk

Overview

The skill appears to build GEO reports from user-provided data, with a file-path handling risk that users should keep scoped but no evidence of deception or exfiltration.

Install only if you need GEO report generation, and pass it explicit report datasets you intend to analyze. Do not let untrusted prompts choose the --data path, and avoid pointing it at broad directories or sensitive files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The manifest description includes broad triggers like creating reports, analyzing performance, building dashboards, and generating insights, which can cause the skill to be invoked in unrelated analytic contexts. Over-broad auto-invocation increases the chance that users or agents apply this skill to data or tasks it was not intended for, potentially exposing sensitive business metrics or producing misleading outputs in the wrong workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal